# Research — Field notes & featured briefs

Latest research from Artifact Lens and the Artifact Security lab.

## Featured · July 2026

### Foot in the door: one calendar invite walked a support agent into full mailbox exfiltration

**AL-2026-014 · injection → escalation**

A supplier's calendar invite carried instructions the target's customer-support agent read as its own. Three tool calls later, it was forwarding mailboxes. The security stack raised seven alerts and blocked nothing. We reproduced the full chain in 9 of 10 runs, handed over a prioritised fix, and verified it held on retest — **the same chain now fails at step one.**

The write-up covers discovery, the injection path, tool-scope escalation, and what actually stopped it.

- Alerts raised: **7**
- Attacks blocked: **0**
- Chain reproduced: **9/10 runs**
- Fix verified on retest: **held**

## Recent field notes

### Shadow agents: the estate you didn't know you deployed
*July 8, 2026 · discovery · 7 min read*

Across our last five discovery runs, roughly a fifth of live agents were unregistered — connected to mail, files, and payments with nobody accountable. How they get there, and how we find them.

### Read-only is a suggestion: tool-chain pivots in MCP-connected agents
*June 19, 2026 · escalation · 11 min read*

An agent scoped to read can often learn to write. We walk through the pivot pattern we now test for by default, and the three configuration changes that shut it down.

### What the EU AI Act actually asks of agent operators
*May 28, 2026 · governance · 9 min read*

Article 15 wants accuracy, robustness and cybersecurity you can evidence. A plain-English map from adversarial test results to the paperwork your board signs.
